Staff Security Engineer

Mozilla
France
Workplace: RemoteFull timeEUR 65,000 - 87,000 annuallyFunction: CybersecurityExperience: 5+ yearsSkills: ["Cross-functional collaboration","Independent execution","Written communication","Verbal communication","Process building"]

Own and continuously improve Mozilla’s Information Security Management System (ISMS), including Statement of Applicability maintenance, risk treatment plans, and Management Review Meeting cadence. Drive ISO 27001 and SOC 2 Type 2 audit readiness by supporting audit execution, evidence/narrative preparation, and resolution of auditor findings. Lead the security policy program and track remediation from readiness assessments while partnering with Engineering, IT, Legal, Privacy, People, and security leadership.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Mozilla
Mozilla
1 day ago

Staff Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Own and continuously improve Mozilla’s Information Security Management System (ISMS), including Statement of Applicability maintenance, risk treatment plans, and Management Review Meeting cadence. Drive ISO 27001 and SOC 2 Type 2 audit readiness by supporting audit execution, evidence/narrative preparation, and resolution of auditor findings. Lead the security policy program and track remediation from readiness assessments while partnering with Engineering, IT, Legal, Privacy, People, and security leadership.
Location: France
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Maintain and mature the ISMS, including Statement of Applicability (SoA), risk treatment plans, and Management Review Meeting (MRM) cadence.
  • •Support ISO 27001 and SOC 2 Type 2 audit execution by defining scope, preparing evidence and narratives, and participating in auditor interviews and walkthroughs.
  • •Contribute to SOC 2 System Description and other audit narrative documentation to ensure they reflect the organization’s actual control environment.
  • •Track gaps and remediation efforts from readiness assessments and audits, ensuring control ownership and closure progress.
  • •Lead the security policy program by driving policy creation, revision, and cross-functional review cycles to keep policies current, enforceable, and audit-ready.

Pay and Benefits

Salary: EUR 65,000 - 87,000 annually
Perks:Health InsuranceDentalVisionHome OfficeLearning BudgetPaid ParentalWell-being Stipend

Key Requirements

  • •5+ years of experience in information security, GRC, or compliance-focused roles.
  • •Hands-on experience with ISO 27001 and SOC 2 Trust Services Criteria through audit involvement from readiness through certification.
  • •Experience maintaining ISMS artifacts such as Statement of Applicability (SoA), Management Review Meetings, and system description documentation.
  • •Proven ability to write, revise, and socialize security policies through cross-functional review cycles.
  • •Experience tracking audit gaps, remediations, and connecting them to broader compliance and risk programs.
Experience:5+ yearsInformation securityGRCComplianceISO 27001SOC 2
Skills:Cross-functional collaborationIndependent executionWritten communicationVerbal communicationProcess building
Certifications:CISACISSPISO 27001 Lead Auditor/Implementer
Languages:English
Tech Stack:ISO 27001SOC 2

Company Brief

Mozilla
Mozilla is a mission-driven organization that builds open-source internet products (notably the Firefox browser) and advocates for an open, private, and secure web through software, research, and community programs.
Industry: Enterprise Software
Company Size: Large (251 to 1,000 employees)
Growth: Nonprofit & NGO
Headquarters: San Francisco, United States
Founded: 1998
Glassdoor
Glassdoor: 2.9
WebsiteLinkedInGlassdoor